Skip to content

Security: prismnetwork-tech/hermes-plugin-prism

Security

SECURITY.md

Security policy

Supported versions

Prism Network projects are pre-production. Unless a repository states otherwise, security fixes apply to the current main branch and no release receives long-term support.

Reporting a vulnerability

Do not open a public issue.

Use GitHub private vulnerability reporting in the affected repository. If that channel is unavailable, email security@prismnetwork.tech with:

  • The affected repository and version.
  • Reproduction steps or a proof of concept.
  • Impact and required prerequisites.
  • Suggested remediation, if known.

Do not include real user data, production credentials or destructive payloads. We will acknowledge a complete report within three business days and provide a status update within ten business days.

Research boundaries

Good-faith research must not access other users' data, degrade public availability, exhaust paid resources, move funds, retain credentials, or use social engineering. Public infrastructure and mainnet contracts are not authorized testing targets unless a separate program explicitly says otherwise.

There aren't any published security advisories